Sophos ITDR · Silver Partner

Catch the attacker before the login becomes a breach.

Sophos ITDR monitors Microsoft Entra ID, watches the dark web for stolen credentials, and detects identity attacks, for Sophos XDR and MDR customers. Buy a licence below, or ask us to size it.

In plain terms: ITDR (Identity Threat Detection and Response) watches for stolen logins and misused accounts, which is how most attackers actually break in today.

Looking for a specific model or SKU? Use the search bar at the top of the page. Or browse the options below.

CapabilityWhat it does
Reduce your identity attack surfaceRuns more than 80 identity posture checks on your Microsoft Entra ID environment to find misconfigurations and security gaps, with clear, actionable recommendations.
Monitor for stolen credentialsScans the dark web and breach databases and alerts you when your users' credentials are exposed, before an attacker uses them.
Advanced identity detectionsDetects kerberoasting, account compromise, stolen credentials, password spray, brute force, and impossible-travel sign-ins, with full MITRE ATT&CK Credential Access coverage.
User behaviour analyticsSpots insider threats and anomalous activity early by measuring against what normal looks like for each user, to prevent account takeover and lateral movement.
Directory infrastructure protectionMonitors changes and suspicious activity in Active Directory and Entra ID and alerts on modifications that could indicate a domain-takeover attempt.
Automated responseTake immediate action: disable accounts, force password resets and MFA re-registration, and isolate the device through Sophos Endpoint.
What is Sophos ITDR?+

Sophos Identity Threat Detection and Response continuously monitors your environment for identity risks and misconfigurations, scans the dark web for compromised credentials, and detects identity-based attacks. It is built on Secureworks Taegis and integrated into Sophos Fusion for Sophos XDR and MDR customers.

What identity attacks does it detect?+

It detects kerberoasting, account compromise, stolen credentials, password spray, brute force, and impossible-travel sign-ins, with full MITRE ATT&CK Credential Access coverage, plus user behaviour analytics for insider and anomalous activity.

Does it monitor for stolen credentials?+

Yes. It monitors the dark web and breach databases and alerts you when user or system credentials have been exposed.

Which identity provider does it cover?+

It runs more than 80 identity posture checks on Microsoft Entra ID and monitors Active Directory and Entra ID for suspicious changes.

Do I need Sophos XDR or MDR?+

Sophos ITDR is a solution for Sophos XDR and Sophos MDR customers. Tell us what you run and we will confirm the right fit when we quote.

Buy Sophos ITDR below  Pick an option to add to cart, or request a quote for volume and monthly pricing.
  • Sophos Identity Threat Detection and Response ITDR - 1 year (100-199 users and servers)

    Sophos Identity Threat Detection and Response ITDR - 1 year (100-199 users and servers)

    $46.00
    MSRP: $48.93
    BUY
  • Sophos Identity Threat Detection and Response ITDR - 1 year (50-99 users and servers)

    Sophos Identity Threat Detection and Response ITDR - 1 year (50-99 users and servers)

    $50.00
    MSRP: $52.69
    BUY
  • Sophos Identity Threat Detection and Response ITDR - 1 year (25-49 users and servers)

    Sophos Identity Threat Detection and Response ITDR - 1 year (25-49 users and servers)

    $60.00
    MSRP: $62.22
    BUY
  • Sophos Identity Threat Detection and Response ITDR - 1 year (10-24 users and servers)

    Sophos Identity Threat Detection and Response ITDR - 1 year (10-24 users and servers)

    $65.00
    MSRP: $69.00
    BUY
  • Sophos Identity Threat Detection and Response ITDR - 1 year (1-9 users and servers)

    Sophos Identity Threat Detection and Response ITDR - 1 year (1-9 users and servers)

    $66.00
    MSRP: $69.00
    BUY